Method for operating an automatic door, window, gate or skylight system
By analyzing behavior patterns and outputting fault signals based on predefined criteria, the method addresses the limited detection capabilities of standard sensors in automatic door, window, and overhead light installations, enhancing fault recognition and operational reliability.
Patent Information
- Application Number
- DE102021200254
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-01-13
- Publication Date
- 2025-10-30
- Estimated Expiration
- 2041-01-13
AI Technical Summary
Existing automatic door, window, and overhead light installations often lack comprehensive error detection capabilities due to limited and standardized sensor systems, failing to recognize faults that are not detected by conventional sensors.
A method that analyzes the behavior patterns of the installation, including actuator systems and control behaviors, to identify faults not detected by standard sensors, outputting fault signals based on predefined behavior patterns and severity levels, facilitating improved fault recognition and cause analysis.
Enhances the reliability of these systems by providing additional fault information, enabling more comprehensive fault detection and aiding in identifying unknown issues, thereby improving operational reliability and maintenance efficiency.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a method for operating an automatic door, window, gate, or skylight system. The invention also relates to a door, window, gate, or skylight system. Such a system typically comprises at least one movable leaf and a drive for the leaf.
[0002] Such systems typically include sensors that can detect system faults; see, for example, DE 10 2015 107 416 B4. However, it is not economical to provide sensors for every conceivable fault in such a system. Rather, the system typically includes only a limited number of sensors, which are often also required by standards. Therefore, only limited fault information is available.
[0003] One object of the invention is to improve the detection of problems in a system of the type mentioned above.
[0004] This problem is solved by a method according to claim 1. This method comprises the steps of: checking the system for the presence of an error signal, i.e., checking the fault state; checking the system for the presence or change of a predetermined behavior pattern of the system; outputting a fault signal if the presence or a change of the behavior pattern is detected but no error signal is detected, and / or outputting a fault signal if the presence or a change of at least one behavior pattern and one error signal is detected.
[0005] The fault signal indicates a problem with the system. This signal is determined based on the system's behavior, particularly the behavior of its actuators and / or control system. Faults are defined as behavioral patterns that are not recognized as errors by the system's existing sensors. The fault signal provides additional information, offering the manufacturer or operator an improved means of resolving system problems that are not typically identifiable as errors. Ultimately, the inventive method allows for the detection of more problems and results in more reliable overall system operation.
[0006] Regarding the monitored fault condition, the cause of the fault is often known and is typically detected by sensors. The output of the fault signal is specifically intended to identify problems whose cause is unknown or can only be determined through analysis.
[0007] According to a further training, the system is designed to record the behavior of the system, whereby recording the behavior includes recording at least one state of the system. Specifically, the system records the behavior of the state, or the behavior of the system itself, which is expressed through the temporal evolution of the state. The state is easy to record; in particular, many well-known systems already have at least some internal state detection capability.
[0008] The at least one state can be, for example, a wing state, a locking state, an operating state, a maintenance state, or a connection state. The state used to determine the system's behavior must be distinguished from the fault state, the negative case of which is a prerequisite for the output of the fault signal.
[0009] A second state or further states, in particular those mentioned above, can also be recorded.
[0010] A state can be captured, for example, in the form of at least one state variable, which can assume different state values.
[0011] A state variable describing a wing state can assume at least one, and in particular any combination, preferably all of the following state values: open, closed, partially open, stopped, opening, closing, pushing shut, unknown, obstruction opening, obstruction closing. The state variable usually assumes only one state value, but it is also possible for two or more state values to be assumed simultaneously (e.g., "open" and "stopped").
[0012] A state variable describing a locking state can, for example, assume at least one, in particular any combination, preferably all of the following state values: unlocked, locked, securely locked, being unlocked, being locked.
[0013] A state variable describing an operating state can, for example, assume at least one, in particular any combination, preferably all of the following state values: normal operation, service operation, learning operation, diagnostic operation, production operation, not initialized, off.
[0014] A state variable describing a maintenance condition can, for example, assume at least one, in particular any combination, preferably all of the following state values: not due, due soon, due.
[0015] A state variable describing a connection state can, for example, assume at least one, in particular any combination, preferably all of the following state values: offline, online, connection setup.
[0016] The specified behavior pattern can include a sudden and / or a gradual change in the behavior of the system.
[0017] The specified behavior pattern can, for example, include the occurrence of at least one predetermined event.
[0018] In an advantageous example, the specified behavior pattern includes a predetermined frequency of a predetermined event, particularly within a predetermined time period.
[0019] An event can, for example, include the occurrence of a state, a predetermined change of state and / or the occurrence or presence of a predetermined group of states at a given and / or arbitrary time.
[0020] The specified behavior pattern can, for example, include a predetermined duration during which at least one state of the system persists.
[0021] In general, for example, repeated and / or frequent occurrences of a predefined behavior pattern can also be detected. Ultimately, problems can be identified by analyzing any number of complex signals and states within the system and issuing a corresponding fault signal.
[0022] According to another example, the frequency of occurrence and / or the duration of a predetermined state is compared with a limit value.
[0023] In particular, the given behavioral pattern may indicate a problem that does not disappear on its own and can be solved especially through active intervention.
[0024] For example, the specified behavior pattern may also be a behavior that indicates a failure to meet an expectation of a user and / or operator of the system.
[0025] The problem and / or its cause may not be detectable by the system's fault sensors. Therefore, the fault signal can advantageously facilitate the detection of such problems and support root cause analysis.
[0026] Preferably, the fault signal can include information about the detected predefined behavior pattern, a possible cause of the predefined behavior pattern, and / or a possible measure to correct a cause of the predefined behavior pattern. This provides the manufacturer, operator, and / or service technician with simple support for the proper operation of the system. In particular, the information can be in plain text format (ID, severity level, self-reset information, title, behavior description, possible causes, possible solutions). This makes the information even easier to read.
[0027] The predefined behavior pattern includes a safety function, specifically the frequency and / or duration of its occurrence. Safety functions are often required by standards or are otherwise desirable. Their activation, in itself, typically does not constitute a fault. However, more frequent activation can indicate a problem that can be identified as a malfunction. For example, a safety function might include stopping a sash, opening it despite a closing command, or closing it despite an opening command, for instance, because an obstruction has been detected. This can be implemented, for example, as part of an anti-pinch function. This behavior is therefore compliant with standards and typically desirable. In this case, repeated activation of the safety function could, for example, indicate a permanent obstruction.
[0028] In particular, it may be provided that the occurrence of a safety function, in particular a safety reaction of the wing, is determined based on a state, especially on a temporal progression of a state, of the system.
[0029] The behavior of the system can also consist of being switched off and / or remaining switched off. This corresponds, for example, to an operating state of "Off". The behavior can also include switching on, initializing, and / or reinitializing the system. These behaviors can also be checked against predefined behavioral patterns. This allows for the reliable identification of further types of malfunctions.
[0030] Furthermore, the behavior of the system can fundamentally encompass the behavior of one or more system components. Thus, for example, the predefined behavior pattern can also include one or more predefined behavior patterns for one or more components. Such components could be, for example, the drive, the wing, a locking device, a drive motor, a communication device, and / or a control device.
[0031] The behavior of the system is usually determined by parameters. Therefore, changing these parameters alters the system's behavior. This can be undesirable and not immediately apparent. For example, it's conceivable that an attacker might maliciously change the parameters. By checking the system's behavior against predefined patterns, the undesirable situation can be easily identified and a fault signal issued.
[0032] When a service technician is on-site or the system is being serviced remotely, an operating state such as "Service Mode" can be activated. This "Service Mode" status can be recorded. If the manufacturer or an authorized service center has not scheduled the technician's visit or the maintenance, a fault signal can also be generated. In this case, too, an attacker could have maliciously activated the service mode. This can therefore be easily detected.
[0033] In another example, the fault signal or a signal derived from the fault signal is provided for and sent to the operator of the plant.
[0034] The object of the invention is further achieved by a method for operating an automatic door, window, gate or skylight system, wherein the system comprises at least one movable leaf and a drive for the leaf, wherein the method comprises the steps: detecting at least one first fault signal and at least one second fault signal, outputting a fault signal depending on the first and the second fault signal.
[0035] Error signals can correspond in particular to error states.
[0036] In a training course, the first and second error signals are intended to indicate the same error and are recorded at different times. This allows for the simple determination of, for example, the frequency of the error in question and the generation of a fault signal from this data.
[0037] The first and second error signals can, for example, relate to different errors. This makes it easy to detect a cluster of errors and / or a predetermined combination of errors and generate a fault signal from it.
[0038] The object of the invention is also achieved by a method for operating an automatic door, window, gate or skylight system, in particular of the type described above, wherein the system comprises at least one movable leaf and a drive for the leaf, wherein the method comprises the steps: detecting at least one first fault signal, detecting at least one state of the system, generating a fault signal with a second severity level depending on the first fault signal and at least one state, and in particular determining the second severity level depending on the first fault signal and at least one state, characterized in that the fault signal is output depending on whether the first and the second fault signal occur within a predefined period and / or at the same time.
[0039] The severity of a fault signal is also referred to as criticality. Severity is an attribute of faults or disturbances. It can be predefined or result from a combination of one or more faults with one or more disturbances and / or one or more state variables. For example, each fault and disturbance can be assigned a specific severity level. If these faults and / or disturbances then occur simultaneously with certain state variables, this can generate a further disturbance signal, which in turn has its own severity level. Therefore, one severity level is assigned to an initial fault signal, and another severity level is assigned to a disturbance signal derived from the initial fault signal and a state variable.As a concrete example, an initial fault signal indicating a defective smoke detector in a fire door can have a certain severity level. If this initial fault signal occurs simultaneously with the door being in the "open" state, a disturbance signal can be generated that has a different severity level than the initial fault signal (in this case, a higher severity level, since a fire door with a defective smoke detector should be closed).
[0040] The method makes it easy to derive additional information about the severity level and allows the system to be operated more reliably.
[0041] The severity level allows an error or malfunction to be assessed as more or less critical. This information can be output to the operator. The status can preferably be a state different from an error state. The severity level can be represented as a numerical value, generated, for example, by formulas that work with parameters assigned to various error signals, fault signals, and / or state variables. It is also possible to label the severity level with descriptive text. A combination of methods is also possible, where, for example, numerical ranges can each be assigned a descriptive text.
[0042] The object of the invention is further achieved by an automatic door, window, gate or skylight system with at least one movable leaf, a drive for the leaf and a control device for the drive, wherein the control device is configured to carry out a method according to the above type.
[0043] In general, the system, in particular the drive or a control unit of the system, may preferably have a communication interface. This communication interface can be used to communicate, for example, behavior, states, error signals and / or fault signals, for example between the system, the manufacturer and / or the operator.
[0044] The system, in particular its drive and / or control unit, may, for example, have a user interface. A user could be, for instance, the system operator. The user interface can be used, in particular, to output a fault signal, a status signal, an error signal, and / or an error state based on the severity of the fault signals present. This allows the user to be easily provided with assistance for the safe operation of the system.
[0045] In principle, the system can include an internet interface, in particular where the fault signal or its severity is transmitted via the internet to a central location, especially the system manufacturer. The internet interface can, for example, be implemented as an NB-IoT interface. Condition monitoring can be performed via the internet interface. In the event of a fault, the system operator can, for example, be notified by email.
[0046] A wing can be, for example, a hinged wing, a sliding wing, a gate leaf, or a tilting wing.
[0047] In principle, the system can include one or more blades and one or more drives.
[0048] The methods described herein can in particular be combined with one another and further developed through their individual features and embodiments.
[0049] Fig. Figure 1 shows a door system 10, which has a leaf 12 and a drive 14 for the leaf 12. Such a door system 10 can, for example, be an automatic door system, such as an automatic sliding door, an automatic revolving door, or an automatic sliding door. The door system 10 can have one, two, or more leaves, which are described together or separately by state variables. A control unit 16 is integrated into the housing of the drive 14. The control unit 16 includes a communication interface 18, which can be configured, for example, as a user interface and / or an internet interface. A line 20 symbolizes a communication network, such as a bus system.
[0050] A defect can be considered a failure to meet technical requirements. In contrast, a malfunction is understood as a failure to meet user expectations, whereby users typically lack technical knowledge regarding the system in question. Here, "user" refers specifically to the operator of such a system.
[0051] A malfunction can occur, in particular, when an anomaly arises that is not recognized as an error. The actual state is recorded, while the target state is unknown. Consequently, the malfunction cannot be, or should not be, recognized as an error because no actual-to-target comparison is possible. Therefore, malfunction detection requires additional information, which is provided to the system as predefined functions or values.
[0052] In particular, the method according to the invention first checks whether an error is present and then checks whether a malfunction is present.
[0053] An example of an error: In a battery, a target voltage is compared with an actual voltage, and if there is a deviation, e.g., exceeding a limit value, an error signal is output or an error state is set.
[0054] Examples of behavior that can generate a fault signal: active safety functions, e.g., over a longer period or with a certain frequency; abrupt changes in the system's behavior pattern; gradual changes in the behavior pattern; changes to control parameters via parameterization tools; initialization; reinitialization.
[0055] In general, with automatic doors, windows, gates or skylights, the detection of malfunctions which cannot or must not be recognized as errors by a control device, especially control logic, can be carried out, in particular on the basis of recurring behavior patterns.
[0056] Detecting and reporting such faults can include the following checks: Are the optionally defined preconditions met? Does the count of defined events exceed a limit?
[0057] A fault signal can be output, for example, when predetermined conditions are met and / or when a change of state occurs from a predetermined first state to a predetermined second state.
[0058] Example: Prerequisites: The system and / or its components are in their intended, fault-free state. Counting: Three state changes from "sash movement not obstructed" to "sash movement obstructed." Reset: After the first count, once the sash states "Open" and "Closed" have each occurred at least once. For example, a state sequence of "not obstructed," "obstructed," "not obstructed" can be recorded. An obstruction, e.g., deceleration / acceleration / stopping of the sash movement, is not a fault in this example, but a permissible event that can occur, for example, through contact between the sash and a person. This triggers, for example, a safety function.
[0059] Example: Prerequisites: The system and / or its components are in a fault-free state. Trigger: When the system's configuration / parameters are changed. For example, if someone changes the configuration, a query is triggered to the user or operator of the system asking if they are aware of the change. This allows for the detection of unintentional changes, such as those made by a malicious third party.
[0060] According to the invention, in automatic doors, windows, gates, or skylights, functions explicitly provided in the control device, in particular the control logic, can be detected as malfunctions if they or the system follow a predefined behavior pattern. In particular, active safety functions with a predefined behavior pattern can also be considered malfunctions.
[0061] Detecting such faults can include checks such as: Are optionally defined preconditions met? Has a condition been met for longer than a defined time limit? Based on this, a fault can be reported. A time measurement, particularly to determine the time limit, can be triggered, for example, by the fulfillment of one or more conditions and / or the occurrence of additionally defined events.
[0062] The above example: Prerequisites: The system and / or its components are in a fault-free state. Trigger: When the system's configuration / parameters are changed. For example, if someone changes the configuration, a query is triggered to the user or operator of the system asking if they are aware of the change. This allows for the detection of unintentional changes, for example, by a malicious third party.
[0063] According to the invention, faults can be detected in automatic doors, windows, gates or skylights which are based on fault accumulation and / or fault combinations of one or more components, in particular faults which are self-resetting.
[0064] Detecting such faults can include checks such as: Are optionally defined preconditions met? Does an error occur more often than a defined limit within a time interval? A fault message can then be issued.
[0065] Example: Prerequisites: none; Trigger: If a battery error occurs at least three times within 24 hours.
[0066] According to the invention, automatic doors, windows, gates or skylights can be dynamically assigned to different severity levels (criticality categories) depending on the system conditions.
[0067] Example: A "Smoke detector defective" error is reported as "critical" if the sash is in the "Open" state. The "Smoke detector defective" error is reported as "non-critical" if the sash is in the "Closed" state.
[0068] The semantics and the number of levels of criticality are basically freely selectable.
[0069] In principle, malfunctions can also be detected when there is a cluster of errors, e.g. non-critical and / or critical errors.
[0070] The condition and behavior of automatic doors, windows, gates, and skylights can be assessed from a user / operator perspective using the methods described herein. For example, if the system exhibits unusual behavior, the manufacturer or a service center can inform the operator: The system is functioning correctly, meaning there is no fault, but there is an unusual behavior that is considered a malfunction. System-specific usage patterns can thus be determined particularly accurately and easily and used to optimize the system.
[0071] The following is a list of some examples of faults. These faults can be output as a fault signal value. Possible causes and remedies are also provided for each fault. The causes and / or remedies can be output along with the fault signal or as part of it, and are shown as examples in the following non-exhaustive list. Due to the nature of fault detection and the constantly growing volume of data, new causes and / or remedies may be added. Malfunction: "Wing open, does not begin to close". Possible causes: Loose connection of the control signal; Push and Go without automatic closing; defective control unit or motor; other / unknown cause. Possible remedies: Check contacts; check configuration and instruct operator; replace material if there is a clear defect. Malfunction: "Wing stops". Possible causes: Factory settings reset. Possible solutions: Check the configuration Malfunction: "Wing does not close completely, opens again". Possible cause: Mechanical blockage; obstacles in the path; configuration Possible remedy: Check the route, remove obstacles; check the configuration. Malfunction: "Wing does not begin to open". Possible cause: Friction; wind load; dirty base rail; worn roller carriage, e.g., unevenly worn or defective; operating state "Off". Possible remedy: Check travel path; measure displacement force, move blades manually. Malfunction: "Wing does not open fully - impairment". Possible cause: mechanical blockage; obstacles in the path Possible remedy: Check the route. Malfunction: "Wing opens slowly". Possible cause: Friction; wind load; mechanical obstruction; dirty base rail; initialization run; learning run; Possible remedy: Check the route; wait for the initialization / learning run to complete. Fault: "System in operating state Off". Possible cause: accidental or intentional switching to operating state Off; in operating state Off for 30 minutes. Possible remedy: Secure the operating mode switch; instruct the operator. Possible fault: "Service mode active". Cause: Service call; accidental access to the service menu; unauthorized access to the service menu. Possible solution: Secure the service menu with a password. Malfunction: Wing does not open fully - closes again. Possible cause: Mechanical blockage; obstacles in the path, configuration; Possible remedy: Check the route, check the configuration Fault: "Wing does not open fully - time". Possible cause: Mechanical blockage; obstacles in the path Possible remedy: Check the route; Disruption: "Opening hours longer than normal". Possible cause: Friction; wind load; mechanical obstruction; dirty base rail; initialization run; learning run Possible remedy: Check the route; wait for the initialization / learning run to complete. Fault: "Closing time longer than normal". Possible cause: Friction; wind load; mechanical obstruction; dirty base rail; initialization run; learning run Possible remedy: Check the route; wait for the initialization / learning run to complete. Fault: "Safety sensor Close (SIS) or Safety sensor Open (SIO) always active in the same location". Possible cause: SIS / SIO activated by wing movement; SIS / SIO activated by environment; Possible remedy: Check SIS / SIO settings; check SIS / SIO capture field. Fault: "Maintenance due - time". Possible cause: The configured maintenance interval of the controller based on operating time has been reached. Possible remedy: Perform maintenance; reset the maintenance message. Error message: "Maintenance due - cycles". Possible cause: The configured maintenance interval of the controller, based on the number of cycles, has been reached. Possible remedy: Perform maintenance; reset the maintenance message. Malfunction: "Wing closes slowly". Possible cause: Friction; wind load; mechanical obstruction; dirty base rail; initialization run; learning run Possible remedy: Check the route; check the SIS data collection field; wait for the initialization / learning run to complete. Malfunction: "Wing does not close completely, remains stopped". Possible cause: Configuration Possible remedy: Check configuration; if there is a clear defect, replace the material. Malfunction: "Wings closed, does not begin to open". Possible cause: Friction; wind load; dirty base rail; worn roller carriage, e.g., unevenly worn or defective. Possible remedy: Check the travel path; measure the displacement force, move the wing by hand. Malfunction: "Wing does not open fully, remains stopped". Possible cause: Factory settings reset Possible solution: Check the configuration. Reference symbol list 10 Door system 12 wings 14 Drive 16 Control unit 18 Communication interface 20 Management
Claims
[1] Method for operating an automatic door, window, gate or skylight system (10), wherein the system (10) comprises at least one movable wing (12) and a drive (14) for the wing (12), the procedure includes the following steps: Checking the system (10) for the presence of an error signal, Checking the system (10) for the presence or change of at least one predefined behavior pattern of the system (10), wherein the predefined behavior pattern includes the detection of at least one safety function Output of a fault signal when the presence or change of at least one behavior pattern and no error signal is detected, and / or output of a fault signal when the presence or A change in at least one behavioral pattern and one error signal is detected. [2] Method according to claim 1, characterized by, that a behavior of the plant (10) is recorded, wherein the recording of the behavior includes that at least one state of the plant (10) is recorded. [3] Method according to claim 1 or 2, characterized by that the condition is a wing condition, a locking condition, an operating condition, a maintenance condition, a fault condition or a connection condition. [4] Method according to at least one of the preceding claims, characterized by , that at least one predefined behavioral pattern includes the occurrence of at least one predetermined event. [5] Method according to at least one of the preceding claims, characterized by that the specified pattern of behavior includes a predetermined frequency of at least one predetermined event, in particular within a predetermined period. [6] Method according to claim 4 or 5, characterized bythat the event includes the occurrence of a state, a predetermined change of state and / or the occurrence or presence of a predetermined group of states at a given time. [7] Method according to at least one of the preceding claims, characterized by , that the specified behavior pattern comprises a predetermined duration during which at least one state of the system (10) persists. [8] Method according to at least one of the preceding claims, characterized by that the given behavior pattern is a behavior that indicates a problem that will not disappear on its own. [9] Method according to claim 8, characterized by , that the problem and / or a cause of the problem is not detectable by a sensor system of the system (10). [10] Method according to at least one of the preceding claims, characterized by, that the interference signal includes at least one piece of information, in particular plain text information, about the recognized predefined behavior pattern, about a possible cause of the predefined behavior pattern and / or about a possible measure to remedy a cause of the predefined behavior pattern. [11] Method according to at least one of the preceding claims, characterized by , that the specified behavior pattern includes recording the frequency and / or duration of the occurrence of the safety function. [12] Method according to at least one of the preceding claims, characterized by , that the fault signal or a signal derived from the fault signal is output to the operator of the installation (10). [13] Method for operating an automatic door, window, gate or skylight system (10), wherein the system (10) comprises at least one movable wing (12) and a drive (14) for the wing (12), the procedure includes the following steps: Detecting at least one first error signal and at least one second error signal, Outputting a fault signal depending on the first and second fault signals, characterized by , that the fault signal is output depending on the first and second fault signals occurring within a predefined period and / or at the same time. [14] Method according to claim 13, characterized by that the first and second error signals are signals of the same error and are detected at different times. [15] Method according to claim 13, characterized by that the first and second error signals relate to different errors. [16] Method for operating an automatic door, window, gate or skylight system (10), wherein the system (10) comprises at least one movable wing (12) and a drive (14) for the wing (12), the procedure includes the following steps: Detecting at least one initial error signal with an initial severity level, Recording at least one state of the plant (10), Generating a fault signal with a second severity level depending on the first fault signal and at least one state and in particular determining the second severity level depending on the first error signal and at least one condition. [17] Door, window, gate or skylight system (10) with a movable wing (12), a drive (14) for the wing (12), and a control device (16) for the drive (14), wherein the system (10) is configured to carry out a process according to any of the preceding claims. [18] Plant (10) according to claim 17, characterized by that the system (10), in particular the drive (14) or a control device (16) of the system (10), has a communication interface (18). [19] Plant (10) according to one of claims 17 or 18, characterized by that the system (10), in particular the drive (14) or a control device of the system (10), has a user interface (18), in particular for outputting the fault signal. [20] Plant (10) according to at least one of claims 17 to 19, characterized by that the system (10) includes a network interface (18), in particular wherein the fault signal or error signal is transmitted via the Internet to a central location, in particular the manufacturer of the system (10).
Citation Information
Patent Citations
maintenance system for monitoring a gate device and method for monitoring a gate device
DE102015107416B4